CVE-2024-21626

GitHub: CVE-2024-21626 Container breakout through process.cwd trickery and leaked fds

Published
February 28, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Why is this GitHub CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in runc which is consumed by Azure Kubernetes Service. The mitigation for this vulnerability requires a security update and a corresponding Azure Kubernetes Service update enables the mitigation. This CVE is being documented in the Security Update Guide to announce that the Azure Kubernetes Service build published on January 31, 2024 is no longer vulnerable. Please see CVE-2024-21626 for more information.

🎯 Affected products3

  • Azure Kubernetes Service
  • CBL Mariner 2.0 ARM
  • CBL Mariner 2.0 x64

✅ Remediation

KBRelease Notes (Security Update) — fixed build 202401.17.2 KBcri-tools (CBL-Mariner) — fixed build 1.28.0-5 KBkubernetes (CBL-Mariner) — fixed build 1.28.4-3

🔗 References (3)